Because we want to limit access to those that can reach winbox for configuring the router.
If you let every tom dick and harry access the input chain ( aka the entire LAN access the input chain) then you have defeated one of the purposes of security and input chain.
Its okay for a startup first config, because the admin can access what he needs.
Thus we only allow admins full access and the users on the LAN really normally only need access to router DNS services and sometimes router NTP services.